Privacy Notice for Requests for Information Received via Email
This document is intended to provide you with detailed information on how Devintec Sagl (“Devintec” or “Controller”) processes your personal data when you contact the company by sending an email to info@devintecpharma.com.
If anything in this notice is unclear, we invite you to consult the “Definitions and Useful Information” section at the end of the document or contact the data controller directly.
1. Who is the data controller and how can I contact it?
Devintec Sagl, with registered office at Corso Elvezia 14 – 6900 Lugano, Switzerland, is the data controller of your personal data. You may contact the Controller at privacy@devitecpharma.com.
2. What categories of data are processed? The processing involves your email address, the content of the message, and any attached files. Based on this information, processing may also involve details such as the subject of your request and your name. It is also possible that processing will involve health and other sensitive data, for example if you contact us to report an adverse event relating to one of our products.
3. For what purposes are the data processed? The controller will only process your personal data for the purpose of answering your request. This data will not be sold or disclosed to the public.
4. How will be my data processed? Once we have received your email, we will deal with it and forward it to the relevant department within our company. In any case, we will delete any unnecessary information. It is also possible that your data will be sent to one or more of our providers who are responsible for the specific activity affected by your request. If we need more information to process your enquiry, we will contact you.
Pharmacovigilance requests
If you send us a report about one of our products, it will be considered part of our pharmacovigilance activities. In this case, your directly identifiable data will be deleted and the information concerning the adverse reaction will be transmitted to the relevant department and to our affiliate company in charge of managing this case.
Clinical trials reporting
If you are taking part in one of our clinical trials and have provided us with the name of the Clinical Centre responsible for your medical treatment, we will forward your request to them. As we do not hold the names of patients taking part in our clinical trials, all information will be deleted once you have contacted the Clinical Centre.
CVs and spontaneous job applications
When you send us a spontaneous job application and/or CV, we will evaluate it and decide whether to delete or keep it. We may also store your data in order to get in touch with you in the future. In any case, CVs are deleted one year after receipt, to ensure the reliability of our database.
5. How long are my data retained? Except in the cases mentioned above, your data will only be stored for as long as is necessary to process the request. This may vary depending on the nature of the request and the related procedure.
6. Who can access my data? The Controller processes data directly through their internal organization, relying on personnel who have been duly appointed and trained, acting as authorized persons. Additionally, external companies may process data on behalf of the Controller, acting as data processors. The Controller is only able to rely on data processors that can guarantee a sufficient level of protection for your data. This is only possible if there is a contractual undertaking to respect specific standards.
7. How are my data protected? Your personal data are protected by adequate security measures. This includes data encryption, regular data backups, and the use of advanced antivirus and intrusion detection systems.
8. Where will be my data stored?
Data will be stored in a server based in Switzerland. It is possible that data will be transferred to countries outside the EEA and Switzerland. In this case, the transfer will only take place once all legal requirements for the transfer have been met, in accordance with applicable law. The Controller only transfer data to countries who provide an adequate level of protection of personal data, relying on the decision of an international organisation (such as the Swiss Parliament or the European Commission) or on the subscription of specific binding clauses.
9. What are my privacy rights?
At any time, and where applicable, you may request from the Controller to access, rectify and delete your data.
If you believe that your personal data have been processed in violation of applicable data protection laws, you have the right to lodge a complaint with the competent Data Protection Authority or take legal action before the competent court pursuant.
10. Definitions and Useful Information
Below you will find a list of definitions and useful explanations to help you understand this notice:
• Processing of personal data: any operation performed on personal data (e.g., storing, reading, archiving, or viewing data);
• Data controller: the entity (or entities) that determine how and why personal data is processed, and that are responsible for ensuring its protection;
• Data processor: third parties who process personal data on behalf of the controller (e.g., IT service providers);
• Data subject: you – the individual whose personal data is processed and to whom this notice is addressed;
• Purpose of processing: the reason the data controller uses your personal data.
